Should have some protection against brute-forcing security codes, especially since `TOKEN_LENGTH` can be set to a low value like 4...
Should have some protection against brute-forcing security codes, especially since
TOKEN_LENGTHcan be set to a low value like 4...